Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CGM CLININET — Vulnerabilities & Security Advisories 24

All 24 CVE vulnerabilities found in CGM CLININET, with AI-generated Chinese analysis, references, and POCs.

This page documents Common Weakness Enumerations associated with the CGM CLININET product developed by CGM. It serves as a centralized resource for tracking security flaws and compliance issues within this specific medical device ecosystem. The vulnerability aggregation page collects data on software vulnerabilities, configuration errors, and integration weaknesses that may impact patient safety or data integrity. The content covers advisory history and disclosed weaknesses from the initial release of the product through the most recent public reports, ensuring a comprehensive view of the product’s security posture over time. By consolidating these records, the page provides a clear timeline of how security issues have been identified and addressed by the vendor. Users can discover detailed information about how CGM has handled specific security advisories, allowing for a deeper understanding of the vendor’s response mechanisms and patch management practices. Additionally, readers can analyze trends within specific weakness classes to understand common implementation pitfalls in medical IoT devices. The page also enables stakeholders to look up the complete vulnerability history of CGM CLININET, facilitating risk assessment for healthcare providers and IT administrators. This structured approach supports informed decision-making regarding system updates, compliance verification, and long-term deployment strategies. The data is organized to help technical teams quickly identify relevant threats and assess the current risk level associated with the product’s version and configuration.

Vendor: CGM

CVE ID Title CVSS Severity Published
CVE-2025-58406 Lack of HTTP Response Headers CWE-693 6.5AI Medium AI 2026-03-02
CVE-2025-58405 Lack of protection mechanisms against Clickjacking attacks CWE-1021 6.5AI Medium AI 2026-03-02
CVE-2025-58402 Insecure Direct Object Reference Message ID CWE-639 7.5AI High AI 2026-03-02
CVE-2025-30062 SQL injection in CheckUnitCodeAndKey.pl CWE-89 9.8AI Critical AI 2026-03-02
CVE-2025-30044 RCE on uhcapache user permissions CWE-78 9.8AI Critical AI 2026-03-02
CVE-2025-30042 Session generation possible with certificate number only CWE-603 6.6AI Medium AI 2026-03-02
CVE-2025-30035 Lack of API authentication allowing session generation for any user CWE-306 9.8AI Critical AI 2026-03-02
CVE-2025-30064 Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key CWE-912 9.1AI Critical AI 2025-08-27
CVE-2025-30063 Excessive permissions on configuration files containing database logins and passwords CWE-732 7.1AI High AI 2025-08-27
CVE-2025-30061 SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameter CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30060 SQL injection in ReturnUserUnitsXML.pl via the UserID parameter CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30059 Authenticated SQL injection in PrepareCDExportJSON.pl CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30058 SQL injection in getPatientIdentifier function of PatientService.pl CWE-89 9.8AI Critical AI 2025-08-27
CVE-2025-30057 Authenticated RCE with uhcapache privileges in ConvertToPDF CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30056 Calling system commands via RunCommand CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30055 Conditional RCE via the "system" function CWE-94 9.8AI Critical AI 2025-08-27
CVE-2025-30048 Unauthenticated access to module configuration endpoint CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30041 Missing authentication in APIs returning statistical data along with session IDs CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30040 Missing authentication in API returning request logs containing session IDs CWE-306 5.3AI Medium AI 2025-08-27
CVE-2025-30039 Missing authentication in API returning a list of all active sessions CWE-306 9.8AI Critical AI 2025-08-27
CVE-2025-30038 Session ID leakage in Zone.Identifier of downloaded files CWE-1230 3.3AI Low AI 2025-08-27
CVE-2025-30037 Missing authentication in APIs allowing data retrieval and modification CWE-306 7.5AI High AI 2025-08-27
CVE-2025-30036 Stored XSS permitting session takeover of arbitrary user CWE-79 7.6AI High AI 2025-08-27
CVE-2025-2313 RCE via Print.pl in uhcPrintServerPrint CWE-94 9.8AI Critical AI 2025-08-27

All 24 known CVE vulnerabilities affecting CGM CLININET with full Chinese analysis, references, and POCs where available.